VMTech
Discuss a project →

P7 DarkSword expands iOS theft tools with wallet extraction and remote commands

P7 DarkSword expands iOS theft tools with wallet extraction and remote commands

Mobile security firm iVerify has identified P7 DarkSword, a previously unseen variant of the DarkSword iOS exploit kit. The variant reduces its on-device footprint, adds local extraction of Keychain and cryptocurrency-wallet data, and establishes two-way command-and-control communication with attacker infrastructure.

DarkSword was publicly documented in March by Google Threat Intelligence Group, iVerify and Lookout after being detected in the wild in November 2025. The kit targets iPhones running iOS 18.4 through iOS 18.7 and chains vulnerabilities to escape the browser sandbox, obtain kernel privileges and inject its principal payload into SpringBoard.

The P7 designation reflects the use of a p7_ variable prefix in modifications to the original code. iVerify said the newer branch removes debug logging over HTTP requests and syslog, and uses browser localStorage to avoid exploiting a device again.

More local processing and interactive control

Earlier DarkSword variants copied the Keychain database and sent it to attacker-controlled infrastructure for processing. P7 instead extracts Keychain information into JSON on the device before exfiltration. Its implant is injected into SpringBoard, the iOS process responsible for app launches and the home screen, which then handles communications with the operator infrastructure.

The implant can send a heartbeat, inventory installed apps and transmit iCloud Keychain information, Apple Notes data, photos and data associated with cryptocurrency wallets. It polls for instructions every 15 seconds. Available tasks include file upload and download, directory listing, filesystem scanning, device-information collection, app-container enumeration, Apple Notes and photo collection, wallet discovery and extraction from the imToken wallet app.

It can also execute operating-system commands, run arbitrary JavaScript in the implant runtime, modify its beacon interval or halt its beacon loop. The command set illustrates how an initial browser-led compromise can become an interactive collection tool on a compromised phone.

Censys finds exposed infrastructure

Censys reported open directories on five hosts containing components linked to DarkSword and Coruna, another iOS exploit kit. It described Coruna as a companion payload kit that runs in the victim's browser session after DarkSword exploit stages land and contains wallet-harvesting modules for recovery phrases, balances and keystore data.

One host served DS-Fusion v1.0, a combined DarkSword and Coruna package. Another acted as a command-and-control server and recorded two Chinese iOS devices polling a beacon page every three seconds for several hours on September 6, 2026. A separate exposed platform was observed polling a device on September 15, 2026.

An analysis of an exploit registry identified CVE-2025-24201, an out-of-bounds write in WebKit fixed in iOS and iPadOS 18.3.2, and CVE-2025-31200, a Core Audio memory-corruption flaw fixed in iOS and iPadOS 18.4.1. Censys suspects the exposed cluster is operated by a Chinese-speaking actor seeking cryptocurrency-wallet theft, although attribution remains unresolved.

Business implication

For organisations with managed iPhones or mobile wallet exposure, the practical priority is to maintain iOS patch compliance, investigate signs of browser-based compromise and include Keychain, application-container and wallet data in mobile incident-response planning.

#iossecurity#mobilemalware#walletsecurity#threatintel
Open analytics
On the site 0 views
min read 4 09.10.2026
Instagram

P7 DarkSword expands iOS theft tools with wallet extraction and remote commands

Open the post on Instagram ↗